I'm trying to make sure that I block emails that originate as servers in
my blacklist, but it's not working.
For example, here are headers from an spam email that came from google,
but originated at 23.171.177.190
Received: from mail-pl1-f232.google.com ([209.85.214.232]
helo=mail-pl1-f232.google.com)
by assp.xmsi.net with SMTPS(TLSv1_3 TLS_AES_256_GCM_SHA384) (2.8.2);
26 Sep 2026 13:52:10 -0400
Received: by mail-pl1-f232.google.com with SMTP id
d9443c01a7336-2df8ecd4f31so6090805ad.3
for<[email protected]>; Sat, 26 Sep 2026 10:52:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=modalmu-com.20251104.gappssmtp.com; s=20251104; t=1790445129;
x=1791049929; darn=mcf.com;
h=content-type:mime-version:date:message-id:subject:reply-to:to:from
:from:to:cc:subject:date:message-id:reply-to:content-type;
bh=1TDJ4xC/XeTexRsJ0r8aoC1Lze3lUcucMSY6MZkOzo0=;
b=LiWXjPhi6lOks+zgcdxJGhjHYO/rZbxd2XTPC7pBrXCAnzoB82/IZyAS0+F+1XsdMt
0J98gOT9oNxvjn5FpchlfpFm5cTHFton1n/IObnHHSEq638oE33eYwlO2bDvPqdtBkVM
Z8pAXbHJ2PrRj4R+Nr4RIVElM6960wgyICPdPbVttLKdldh9mXMC79EaGgWop4ru35lk
vbKuIgWA2iuREuT9dcbFtE4XXRbNDEEeJ9dWUlcBOfYkx3XdOOT6rQTsZc0cDZbsMarc
xFE9ZDZkT9BRqCO2OvYLkdfYp7iZjEt76wurd3uetFD96Qw0WvoIkjogefBtvtwJ3CNm
S0fw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20260707; t=1790445129; x=1791049929;
h=content-type:mime-version:date:message-id:subject:reply-to:to:from
:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id
:reply-to:content-type;
bh=1TDJ4xC/XeTexRsJ0r8aoC1Lze3lUcucMSY6MZkOzo0=;
b=TAmfj3qxbsf8xcclcz++876oG/lVhvhmyoFmVFxz5Prq58TpzlPHmirmp1YnfX1zQ0
YnHI7x0E9wzkilMGcxYCrASVzbtkKssPVfBEPTxonZqlnF5AdYfmPCelfz9b4CVlBCIU
TZxn1XEGIcUBaYAK7+5xOraFsT/YqEIJ7w1P3jQBKD6D3T7Du+vJvh06VR0EiPcmp75a
AgBkelgIpRlJSEZIsriAf3J9SUiae85w4NO2dR2KH2+L9ah2BppFEydiccAQBYb+wOpB
pMlw7mysY3RYiLoZPdVBq+rbew7GqHGVePI0XV3jARy5cb8f/oit1f1ukv5EDRN5bWfG
b84w==
X-Gm-Message-State: AFq9FYIPjP1mP+bHn/UflH+3xGIL6HnGAqxC2rSwT1rwkaRwS9vKt4uU
qnpgP6V98ldH4gnpgP7HUGSBlf1ecNdKEgG9/ji5VShD5xEjxfqRuUGVFxUDbyyji7cG5nbbLz/
OsHv4wuRGeAPwsPA96q+zZBJmuxx/wz//vB2sM4EcuM806Xk=
X-Gm-Gg: AYBFou30RtYLSMdqG6qSPUI18+Mu+ZlUwb8akqXwqHlZIPirKlw0wuAoSFr8qcEDely
VA27C4CXZRfEX6oaAimjPS/j+XIU/VQ+C+5dNXnhgSycmGV2s4gAv0dOSTvm5dGjQvfsM/6gv9Q
E59KrGL3VbIKLrekb64XUn57KgmELotNao4FnzniR+WcPOUZuhp0Z6dBXqSP2GMdY+115q62ELA
ZcCEn2SAirSOGxXdwJn8cGjN4S8bCKZu/gpMWMHALsloCrD/sLB89cZEPicAS2QHHEc3cKxNBa2
/WZXm2AW8lUBfQVjtX22TCX1JSP8fCMoC3Ur/l7rTLUkSnk/3IEerEB8S/6Bef6sejkQbQgqZOX
FrJLuDKCsPbUOYanGUZ3mpA==
X-Received: by 2002:a17:90b:2d05:b0:3a0:cde8:1dbb with SMTP id
98e67ed59e1d1-3a0cde82a18mr3056034a91.22.1790445129403;
Sat, 26 Sep 2026 10:52:09 -0700 (PDT)
Received: from brainworks.id ([23.171.177.190])
by smtp-relay.gmail.com with ESMTPS id
98e67ed59e1d1-3a0b8c75bfesm3708483a91.0.2026.09.26.10.52.09
for<[email protected]>
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Sat, 26 Sep 2026 10:52:09 -0700 (PDT)
X-Relaying-Domain: brainworks.id
From: Paul Carter<[email protected]>
To:[email protected]
Reply-To:[email protected]
Subject: =?UTF-8?B?SW1wb3J0YW50IGRvY3VtZW50IGZvciB5b3U=?=
Message-ID:<[email protected]>
Date: Sat, 26 Sep 2026 17:52:05 +0000
MIME-Version: 1.0
Content-Type: multipart/related; type="text/html";
boundary="--_NmP-f20bb18738df8c0d-Part_1"
23.171.177.190 is in a blacklist (when I check it in the IP check it shows is
in pbBlack).
When I run the mail analyzer over the email, it doesn't show as checking the
23.171.177.190:
*•DoNoFrom <https://10.185.0.23:55555/#DoNoFrom>*: OK - mode is
scoring *•DKIM-check returned OK*verified-OK for
identity'@modalmu-com.20251104.gappssmtp.com' *•SPF-check returned
OK*for209.85.214.232->[email protected],
mail-pl1-f232.google.com •SPF: softfail (cache)
[email protected]=mail-pl1-f232.google.com
*•URIBL check <https://10.185.0.23:55555/#ValidateURIBL>*: 'OK'
*•*legacy attachment levels are not checked - please
configureUserAttach <https://10.185.0.23:55555/#UserAttach> *•*legacy
attachment levels are not checked - please configureUserAttach
<https://10.185.0.23:55555/#UserAttach> *•*legacy attachment levels
are not checked - please configureUserAttach
<https://10.185.0.23:55555/#UserAttach> *•*legacy attachment levels
are not checked - please configureUserAttach
<https://10.185.0.23:55555/#UserAttach> *•Valid Format of HELO
<https://10.185.0.23:55555/#DoValidFormatHelo>*:
'mail-pl1-f232.google.com' *•IP in Helo check
<https://10.185.0.23:55555/#DoIPinHelo>*: 'OK' *•AUTH would be
disabled* *•209.85.214.232is inPB Black
<https://10.185.0.23:55555/#pbdb>*: score:185, last event -
URIBLneutral *•IP209.85.214.232used a secure socket layer*
*•RBLCacheCheck returned OK for209.85.214.232*: inserted as ok at
2026-09-26 13:52:12 *•domain brainworks.id (in Mail From: , From) has
a valid MX record*: ASPMX.L.GOOGLE.COM *•domainMX ASPMX.L.GOOGLE.COM
has a valid A record*:172.253.122.27 *•domain zscehnice.cz (in
Reply-To) has a valid MX record*:
zscehnice-cz.mail.protection.outlook.com *•domainMX
zscehnice-cz.mail.protection.outlook.com has a valid A
record*:52.101.209.153 *•209.85.214.232PTR record by DNS*: status=PTR
OK - mail-pl1-f232.google.com *•209.85.214.232SenderBase*: status=not
classified, data=[CN=US, ORG=GOOGLE INC., DOM=google.com, BLS=, HNM=,
CIDR=17, HN=mail-pl1-f232.google.com]
Could it be because of the fact that the received header for that IP
says "Received: from" instead of "Received: by"?
I have enhancedOriginIPDetect set to all, not the default all but most
origin.
I'm running 2.8.2 build 26253
Any ideas?
Thanks.
--
Farokh
----------------------------------------------------------------------------
Best Tech Service, LLC - When only the Best Tech will do...
For all your technology needs including hosting solutions.
Office: 845-735-0210
Cell: 914-262-1594
Like us on Facebook:https://www.facebook.com/besttechsvc
_______________________________________________
Assp-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-user